sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 6.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.1 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Aix 7.2 Openssh_advisory9 | — | — | Dec 19, 2016 | Dec 19, 2016 |
| Alpine Linux | — | Upgrade openssh | Aug 30, 2017 | Feb 13, 2017 |
| Amazon_linux | — | Upgrade openssh | Oct 3, 2017 | Jul 24, 2016 |
| Centos_linux | — | Upgrade openssh-keycatUpgrade openssh-server-sysvinitUpgrade openssh-clientsUpgrade openssh-debuginfoUpgrade openssh-cavsUpgrade openssh-serverUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-ldap | Sep 1, 2017 | Jul 24, 2016 |
| Debian | — | Upgrade openssh | Jul 24, 2016 | Jul 24, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 23, 2016 |
| Freebsd | — | Upgrade openssh-portable | Dec 10, 2025 | Sep 1, 2016 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade openssh-askpassUpgrade openssh-serverUpgrade opensshUpgrade openssh-clientsUpgrade openssh-keycat | Nov 30, 2017 | Feb 13, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssh-serverUpgrade openssh-keycatUpgrade openssh-askpassUpgrade opensshUpgrade openssh-clients | Nov 30, 2017 | Feb 13, 2017 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory9 | Nov 30, 2017 | Feb 13, 2017 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 7.3 | Mar 13, 2017 | Feb 13, 2017 |
| Oracle Solaris | — | Upgrade network/openssh to version 7.3.0.1-0.175.3.15.0.2.0 on Solaris 11.3Upgrade system/library to version 0.5.11-0.175.3.28.0.4.0 on Solaris 11.3 | May 29, 2017 | Feb 13, 2017 |
| Oracle_linux | — | Upgrade opensshUpgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh-cavsUpgrade openssh-serverUpgrade openssh-server-sysvinitUpgrade openssh-ldapUpgrade openssh-keycatUpgrade pam_ssh_agent_auth | Aug 8, 2017 | Jul 14, 2016 |
| Panos | — | Update PAN-OS 6.1 to the latest workaround for your deviceUpgrade PAN-OS 7.0 to the latest versionUpdate PAN-OS 6.0 to the latest workaround for your deviceUpdate PAN-OS 7.1 to the latest workaround for your device | Nov 18, 2016 | Jul 24, 2016 |
| Redhat_linux | — | Upgrade opensshUpgrade openssh-cavsUpgrade openssh-ldapUpgrade openssh-debuginfoUpgrade openssh-serverUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-server-sysvinitUpgrade openssh-keycatUpgrade openssh-clientsNo solution exists | Aug 3, 2017 | Jul 24, 2016 |
| Suse | — | Upgrade openssh-fipsUpgrade opensshUpgrade openssh-clientsUpgrade openssh-askpass-gnomeUpgrade openssh-commonUpgrade openssh-askpassUpgrade openssh-openssl1-helpersUpgrade openssh-openssl1Upgrade openssh-serverUpgrade openssh-helpers | Sep 12, 2016 | Jul 24, 2016 |
| Ubuntu | — | Upgrade openssh-server | Aug 17, 2016 | Jul 24, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub